CVE-2024-23564
A critical flaw in HCL Aftermarket EPC lets an unauthenticated attacker trick the system into sending user passwords to an email address of the attacker’s choice. The vulnerability arises because the application fails to validate email requests, allowing password disclosure. This could expose many users’ credentials.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
HCL Aftermarket EPC (all versions; no specific CPE listed).
Real-world impact
An attacker could obtain the passwords of any user and have them sent to an email address they control, enabling account takeover or further compromise.
Why this severity
The CVSS score of 9.1 reflects that the flaw can be exploited over the network without authentication, with low effort, and it gives the attacker full confidentiality and integrity compromise of user credentials.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources